More false alarms?

Hi,

I just got the following report while the malware scan from another program was running;

C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe

Win32:Malware-gen

Virus/Worm

100112-0, 12/01/2010

This program has been installed and running for years - literally.

Am I going to have to switch off standard shield to avoid having large chunks of my system deleted - or flagged actually as I never let antthing delete files without my interaction.

Any timeframe on a fix?

dr del

Had the same exact thing happen to me tonight during boot-up. I’ve used Diskeeper for years no problems.

Hopefully an avast! update will be out shortly addressing this “false positive”. ???

Kris

Hi dr del,

Welcome to the avast forum
Please submit to : virus@avast.com or you can submit from your chest

If you submit through email :

  1. Compress the file with .zip and the file name :virus
  2. Protect with password : virus

Hi,

Reported via email as I did not allow avast to move the file knowing it to be a false positive.

Sent as per your instructions above.

dr del

Hi dr del,

Sure, that’s good if you already noticed to ALWIL virus Lab that your application not really react as Malware Gen anymore.

This happened with me to last nite, i got 2 applications which detected as Malware and PUP Gen in my notebook.

My brother’s PC just popped up with the same warning message. He was about to delete the dkservice.exe but luckily called me through first.

AutoFAT.exe in %windir%\system32\ also came up with the same warning.

I’m having the same problem with Diskeeper.

Did you follow the advices on reply #2 ?

I submitted both my “infected” files to Kaspersky’s File Scanner (Zipped) and they both got Clean reports.

Scanned file: DkService.zip DkService.zip/DkService.exe - OK

Statistics:
Known viruses: 3305480 Updated: 13-01-2010
File size (Kb): 419 Virus bodies: 0
Files: 1 Warnings: 0
Archives: 1 Suspicious: 0

Scanned file: AutoFAT.zip
AutoFAT.zip/AutoFAT.exe - OK

Statistics:
Known viruses: 3305480 Updated: 13-01-2010
File size (Kb): 72 Virus bodies: 0
Files: 1 Warnings: 0
Archives: 1 Suspicious: 0

:-\

VirusTotal Results:

DkService.exe


http://img15.imageshack.us/img15/603/virustotal1.th.png

AutoFAT.exe


http://img15.imageshack.us/img15/603/virustotal1.th.png

fixed VPS is currently being released…

Hi,

Installed the update and re-enbled the standard shield and no more FP’s so far. 8)

dr del

I’ve updated what it tells me is the latest version, 100113-0, but am still getting a warning about the autofat.exe mentioned above, so have sent that file in for confirmation that it is a false positive. There were clearly two alerts being issued initially, and I wonder if only one of them has been fixed?

I’ve updated what it tells me is the latest version, 100113-0, but am still getting a warning about the autofat.exe mentioned above, so have sent that file in for confirmation that it is a false positive. There were clearly two alerts being issued initially, and I wonder if only one of them has been fixed?
[/quote]
I’m also having the same issue but with Avast! 5.0.332 with vps 100113-0, the file autofat.exe is detected as Win32:Malware-gen :frowning:
Hope to see this fixed soon :slight_smile:

Someone just called me for tech support worried they had a virus on their computer with the same files mentioned above. Is a fixed definition on the way today sometime?

Cheers!

Hi,

Just tested and it does the same here - looks like a few have still slipped through the net. :frowning:

A new update arrived for me while I was typing this;

  • Vps: Updated
    (previous version: 100113-0, updated version: 100114-0)

And it no longer seems to see it as a threat. ;D

Any others to check or are we in the clear?

dr del

After the last update the fp is gone :). Problem solved! :smiley:

Same here. I just checked the two files and no false alarms :slight_smile:

Thanks for the quick fix, avast! ;D

Fixed for me too, thanks.